Otto operates a web page at every autonomy level through readable elements. Only at the autopilot level does a second path get added: a picture of Otto’s own hidden window, and a click on a point in that picture — never at the user’s real pointer, never for money, sign-in, consent or an unlabelled target.
Contents
Docs overviewScreen · Autopilot & pointer control
A window of its own, a pointer of its own
Two paths lead to a web page: the path through readable elements (at every level) and the path through an image with a click on pixels (autopilot only). Both run in a hidden Electron window with its own browser profile — the user can keep working undisturbed in the meantime.
The ten browser tools
- Open page · read
- Approval class “read” — navigating to a page or reading its content changes nothing.
- Scroll · wait · screenshot
- Also “read”: scrolling, waiting for an element, photographing the page or saving it as a PDF.
- Click · fill in fields
- Approval class “send” — a click can trigger something on someone else’s page that nobody can take back.
- Manage session
- Also “send”: clearing the keychain discards logins, “sign in” leads to a real sign-in with a third-party service.
- Submit a form
- Highest approval class “geld_oder_loeschen” — at that moment, everything in the form goes out.
- Manage tabs
- Opens, switches and closes browser tabs — tested at the core, but unlike the other browser tools, not yet at the interface itself (see gaps below).
All of it counts as foreign content — Every browser tool carries the “foreign content” flag — even the ones that look like pure action at first glance. After every click the page is read again, and a tab title is also text someone else wrote. From the first glance onward, the whole run counts as having touched foreign content, and the approval desk checks everything that goes out afterwards.
Pointer control — autopilot only
These tools do not exist at all in the “always ask” and “balanced” levels — the lock sits on the toolbox itself, not on a card the model could click away. Clicks land exclusively in Otto’s own hidden window; the user’s system pointer is never touched.
Five spots it never clicks or types into
- Sign-in Refused, no card
- Password, username and one-time-code fields, plus sign-in buttons — the user signs in themself.
- Consent · CAPTCHA Refused, no card
- Otto may click “decline” or “necessary only”, never “accept” — and it does not try to get past a human check.
- Secret-looking value Refused, no card
- If the value about to be typed looks like a card number, an IBAN or an access key, Otto types it into no field at all — regardless of how the field itself is labelled.
- Money · the irreversible Approval card instead of a click
- Paying, ordering, cancelling and permanent deletion get put in front of the user instead of clicked automatically.
- Unlabelled target Approval card instead of a click
- An operable element with no readable label at all gets a card — “unknown” means “stricter” here, not “overlooked”.
Known gaps in this documentation build (as of 25 Sept 2026)
- Four of the six autopilot pointer tools (open/close the pointer window, view the image, drag, scroll) run without any automated test at all — only click and type are partly tested.
- The browser tools themselves run in the integration test against a stand-in page driver, not against a real browser with real forms, anti-bot protection or JavaScript frameworks.
How it works — the three autonomy levels in detail Back to the screen memory